A system that enables the conversion of Enterprise Resource Planning (ERP) event logs into reasoned and confidence-scoring technical recommendations at the license level.
Patent Information
- Application Number
- TR202614902
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-09-01
- Publication Date
- 2026-09-21
Smart Images

Figure 00000019_0000
Abstract
Description
1 TARIFF ENTERPRISE RESOURCE PLANNING EVENT LOGS, LICENSE TECHNICAL ANALYSIS WITH JUSTIFICATION AND CONFIDENCE SCORE REGARDING THE LEVEL. A SYSTEM THAT ENABLES THE CONVERSION OF INTO RECOMMENDATIONS. Technical Area This invention analyzes heterogeneous event logs generated in enterprise resource planning. standardization of user / service account behavior in technical terms classification, the discrepancy between the authorization matrix and the actual transaction depth is 10 calculation and computer-aided generation of the license level proposal It is related to a system that provides. Previous Technique In the known state of the art, corporate license tracking mostly involves static user-roles. matching, license key verification, service request-based access control, or This is carried out through periodic inventory reports. These methods verify the existence of the license. or can show what role the user has; however, the user's actual role which module and at what depth the operation is performed, service / application programming intermediate 20 How Application Interface (API) accounts are structured to resemble human user behavior that they are separated and that the background integrations indirectly provide licensed functions It is technically impossible to determine whether or not it triggered it. The known technique... The key deficiency in this approach is treating access permission and actual license consumption as the same thing. It means that a user has been granted authorization, that user has access to high-level 25. That doesn't necessarily mean it needs a license. Similarly, a service... the application programming interface or batch / stack application for a specific module of your account Access via (batch) channel, license not visible in classic user lists This can lead to increased consumption. Therefore, only the user list, session count, or Systems that check license keys are unable to detect technical deviations. 30 2 Major technology companies around the world that produce enterprise resource planning software, and Global providers developing software asset management tools are the main players in the market. They are players. Existing solutions mostly involve license inventory, user list, It offers rule-based alerting, contract management, or cost reporting functions. A significant portion of these tools are behavioral event vectors, authorization-use divergence 5. score, API / batch-derived indirect consumption verification, and manager feedback. an integrated active learning structure that updates model thresholds with notifications It does not present it as a technical process. Therefore, considering the studies and shortcomings in the current technology, 10 when considered, heterogeneous Enterprise Resource Planning (ERP) The inability to reduce (ERP Planning) logs to a common event model is human Technical data on consumption originating from the user-service / application programming interface. The inability to separate them, the difference between allocated authority and actual transaction depth. 15 that cannot be automatically measured and is not visible in classic access reports the inability to reliably label indirect license consumption Problems include a standard event vector, license consumption-specific scores, and contextual factors. anomaly detection, license matrix validation, and active learning feedback a system is needed that allows it to be solved through its mechanism It is understood. 20 International patent number WO2015019315A1, which falls under the prior art. The document mentions an ERP system. This invention is small and... It relates to a smart ERP designed for medium-sized businesses. Real-time 25 single integrated ERP system, nine core modules and sixteen optional modules It consists of and reduces maintenance time, licensing fees, and also management. a self-hosted, cloud-based system providing a real-time dashboard or software-as-a-service (SAAS) is available as a computing infrastructure. Brief Description of the Invention 30 3 The purpose of this invention is to explore different approaches in enterprise resource planning processes. generated sessions, roles, modules, processes, application programming interfaces, batches, and converting service account records to a standard event vector, extracting technical attributes specific to license consumption from vectors, human user, service / application programming interface account and batch originating actual 5 the separation of consumption, the three-stage process of indirect or hidden license consumption verification method, licensing catalog and authorization restrictions in order to ensure that the applicable license level is proposed below It is about implementing a developed system. Detailed Description of the Invention "Enterprise Resource Planning" was implemented to achieve the purpose of this invention. Event Logs, Technical Data with Justification and Confidence Score Relating to License Level A system that enables the conversion of suggestions into recommendations is shown in the attached document, 15 this shape; Figure 1 shows a schematic view of the system that is the subject of the invention. The parts shown in the figure are individually numbered, and these numbers correspond to 20. The corresponding answers are given below. 1. System 2. Data Collector and Resource Matching Module 3. Standard Event Vector Normalization Module 25 4. Feature Extraction Module 5. Undergraduate Class Contextual Segmentation Module 6. Indirect / Hidden License Consumption Detection Module 7. License Deviation Score and Eligibility Decision Module 8. Constraint-Based Optimization and Licensing Recommendation Module 30 9. Notification Module 4 10. Active Learning and Model Updating Module Heterogeneous event logs generated in enterprise resource planning standardization of user / service account behavior in technical terms classification, the discrepancy between the authorization matrix and the actual transaction depth is 5 calculation and computer-aided generation of the license level proposal The system in question, developed for the purpose of providing (1); - session logs, module / screen accesses, transaction logs, API calls, batch jobs, service account activities, user-role Collecting matchmaking, authorization matrix, and license catalog data, 10 raw ERP event data, authorization matrix and license catalog at least one piece of data structured to enable them to be collected together collector and resource matching module (2), - raw records account type, role, module, transaction, channel, time window and 15 standard event vectors including existing license class fields. at least one standard structured to enable its conversion event vector normalization module (3), - a variety of modules specific to license consumption, ranging from standard event vectors, transaction depth, API / batch density, authorization-use deviation, and licensing. 20 structured to enable the calculation of fitness scores at least one feature extraction module (4), - User and service accounts based on current license class, role-authority to segment based on similarity and behavior vector at least one structured undergraduate class contextual segmentation module (5), 25 - Rule for indirect consumption candidates originating from APIs, services, and batches. based pre-filter, contextual anomaly score, and licensing matrix at least configured to enable tagging with verification an indirect / hidden license consumption detection module (6), - assigned high-level permissions, unused modules, process 30 depth, passivity, indirect consumption risk, and the scope of the mandatory work module. By evaluating this information together, a license deviation score is calculated. at least one license deviation score configured to calculate and suitability decision module (7), - Proposed license applicable with constraint-based objective function To ensure the level is determined, the confidence score of the proposal, technical 5 to ensure that it is produced along with the justification and license deviation score At least one constraint-based optimization and licensing proposal is structured. module (8), - the recommended license level for each user and service account, generated confidence score, generated license deviation score, generated indirect consumption 10 risk, affected modules and the technical rationale of the proposal The data is presented in the form of a heat map, trend, risk ranking, and action list. presenting which technical events led to the proposal structured to produce an output in the form of a describable record set at least one notification module (9), 15 - Model coefficients and thresholds of administrator approval / rejection data to be used as active learning input for updating at least one active learning and model structured to provide It includes update module (10). Data collector and source matching module in the system (1) that is the subject of the invention (2), session logs, module / screen accesses, transaction logs, application Programming interface (API) calls, batch / stack tasks, service account activities, user-role mappings, authorization matrix, and Collecting license catalog data, records; timestamp, account type, access 25 Matching via channel and module ID, screen belonging to the same process chain, API and associating batch records with correlation ID, allocation with actual consumption. data to enable technical comparison between acquired license levels It is structured to provide this. 6 Standard event vector normalization module in the system of invention (1) (3), heterogeneous log formats, Enterprise Resource Planning (Enterprise Resource Planning (ERP) license consumption analysis specific to the e-event vector convert, mark missing fields according to source reliability, duplicate Extracting records using transaction-time-calculation correlation, events at fixed time 5 separating into windows, time window synchronization, identity masking, account type classification, access channel separation, duplicate event cleaning, and correlation performing processes such as identity generation, for license analysis to enable the production of comparable technical data models It is being structured. 10 In the system that is the subject of the invention, the feature extraction module (4) in (1) event Generating numerical and categorical attributes specific to license consumption from vectors, Transaction depth, module variety, API / batch density, role-authority coverage rate and is structured to calculate the license deviation score. Attribute 15 inference module (4), the number of accessed unique modules is the number of authorized modules A module is configured to calculate a diversity score by dividing it into parts. The feature extraction module (4) calculates the weighted processing score according to the relevant license class. Calculate a trade depth score by dividing it by the maximum trade score it yielded. Reading, writing, approving, data exporting, and management operations with different weightings 20 It is structured to multiply. The feature extraction module (4) reads and Dividing the reporting event count by the number of write, approval, and management events to create a read-only report. It is configured to calculate the write rate. Feature extraction module (4), divide the number of API and batch originating events by the total number of events to form an API / batch It is configured to calculate the density ratio. Feature extraction module 25 (4) divide the number of off-hours API / batch events by the total number of API / batch events. It is configured to calculate the off-hours automation score. Attribute inference module (4), count of days since last successful interaction to calculate a passivity score by dividing it into evaluation windows It is being structured. The attribute extraction module (4) actually uses the following permissions: 30 by dividing by assigned authorities to calculate a role-authority coverage ratio 7 It is being configured. The feature extraction module (4) has an unused high-level the weighted total of usage candidates exceeding the authorization and license class to calculate an authorization-usage deviation score by dividing it by the scope of authorization It is structured. The feature extraction module (4) calculates the license eligibility score: w1*Termination Depth+w2*Module Diversity+w3*Required Module Scope-5 Calculate using a formula like this: w4*passivity-w5*indirect consumption risk It is structured accordingly. The inventive system includes a license class contextual segmentation module (1) (5), user and service accounts existing license class, role-authority similarity and 10 Segmenting user behavior according to behavior vectors, role-authority normalizing similarity using Jaccard or cosine similarity, same license class clustering the behavior vectors of accounts with similar role scopes, expected consumption within the same license class instead of general user behavior It is designed to measure deviations from the pattern. 15 The indirect / hidden license consumption detection module (6) in the system (1) that is the subject of the invention, API, service account, or batch-based consumption uses technical methods specific to license consumption. Treating it as an event class, APIs and services that are not visible in classic access reports. Account and batch-related consumption have been classified as verified technical event class 20. It is configured to bring about indirect / hidden license consumption detection module. (6), high frequency module access without human user session, same service The account triggers modules belonging to multiple role classes, the batch query Extracting data or using a reporting channel outside the scope of a licensed module is not permitted. If the screen function is called in the background, the event is classified as a "potential indirect consumer" 25 It is structured to be marked as such. Indirect / hidden license consumption. Detection module (6), candidate events; same undergraduate class, same role-authority similarity and same to evaluate based on normal human user behavior within the time window, API / batch density, after-hours automation score, and data volume components. It is structured to calculate contextual anomaly scores. Indirect / hidden 30 License consumption detection module (6), triggered by the event marked as an anomaly 8 module, transaction type and data object with mandatory license class in the license catalog to match, event if the match is incompatible with the existing license or role scope. to label as "verified indirect license consumption" It is structured. Indirect / hidden license consumption detection module (6), indirect Consumption confidence score: a*pre-filter score + b*anomaly score + c*license matrix 5 Calculating using a formula in the form of a non-conformity score, indirect consumption Constraint-based optimization when the confidence score is above a defined threshold. and to transfer it as a risk input to the license proposal module (8). It is being structured. License deviation score and suitability decision module in the system (1) (7), compare the available license class for each account with the actual usage requirement, License deviation score; assigned high-level permissions, unused modules, depth of operation, passivity, indirect consumption risk, and mandatory work module scope. By evaluating the information in this form together, the calculation is made, and the calculated score is 15 The account's current license is excessively high, insufficient, incompatible, or indirect. to determine which of the consumption risk classes it falls into It is being structured. Constraint-based optimization and license proposal 20 included in the system of invention (1) module (8), Min F (L') = Cost (L') + λ1* Compliance Risk (L') + λ2*Business Continuity The objective is expressed as: Impact (L') + λ3* Indirect Consumption Risk (L'). Solving the function, constraints; mandatory module scope(L')>= actual mandatory module need, processing depth capacity(L')>= observed processing depth, compatibility To define risk(L') <= threshold, business continuity impact(L') <= threshold, this function is 25 As a result, it preserves minimum authority, keeps technical risk below the threshold, and the existing to determine the recommended license level that meets the usage requirements It is structured. Constraint-based optimization and license proposal module (8), Current license, proposed license, mandatory module scope, processing depth capacity, factors such as compatibility risk and indirect consumption risk together 30 9 to evaluate by calculating an objective function, without violating technical constraints It is structured to enable the selection of a more appropriate license level. Notification module (9) in the system (1) which is the subject of the invention, each user or service Recommended license level for the account, generated confidence score, generated license deviation 5 The score, the indirect consumption risk generated, the affected modules, and the technical aspects of the proposal. The data presented as justification includes a heat map, trend, risk ranking, and action list. presenting it in a way that shows which technical events led to the proposal. It is configured to produce an output in the form of a descriptable record set. Active learning and model update module in the system (1) which is the subject of the invention (10), suggestions approved, rejected or manually corrected by the manager To use model update data, approved proposals are subject to the relevant license. Storing rejected proposals as confidence-building examples for the class is considered "mandatory work". 15 with the labels “need”, “temporary project use”, “exceptional authorization” or “false positive” adding to the training pool, model weights, anomaly thresholds, and indirect Updating consumer confidence score coefficients periodically, thus preventing errors. to reduce positive and false negative rates It is being structured. Industrial application of the invention The system of invention (1) normalizes heterogeneous events, license generating consumption-specific scores, indirect consumption candidates, anomaly score combining the licensing matrix verification with labeling, employee 25 by converting technical event logs in systems into a standard event vector behavioral segmentation, contextual anomaly detection, license deviant score, and constraints. generating recommendations based on data models specific to ERP license consumption. and score generation flow from human user, service / API and batch sources. technically decomposing consumption, heterogeneous ERP records (log) into a single 30 converting it to an event model, human user and service / API account consumption the separation, the discrepancy between the authorization matrix and the actual transaction depth measuring indirect license consumption without the need for manual review marking, improving the accuracy of the suggestion through feedback, this technique As a natural consequence of the outputs, reducing unnecessary license allocation in institutions, reducing the risk of non-compliance and audits, in large user pools 5 This helps reduce the need for manual control. Around these fundamental concepts, the invention topic is the “Enterprise Resource Planning Incident”. Their records include a reasoned technical explanation and confidence score related to the License Level. There are many different 10 related to "A System that Enables the Transformation into Suggestions (1)". It is possible to develop applications, and the invention is illustrated with the examples described here. It cannot be restricted, it is essentially as stated in the claims.
Claims
11 REQUESTS 1. Heterogeneous event logs generated in enterprise resource planning. standardization of user / service account behavior in technical terms classification, the 5 between the authorization matrix and the actual transaction depth Computer-aided calculation of the deviation and license level recommendation developed to enable its production in this way; - session logs, module / screen accesses, transaction logs, API calls, batch jobs, service account activities, user-role Collecting matchmaking, authorization matrix, and license catalog data, 10 raw ERP event data, authorization matrix and license catalog at least one piece of data structured to enable them to be collected together collector and resource matching module (2), - raw records account type, role, module, transaction, channel, time window and 15 standard event vectors including existing license class fields. at least one standard structured to enable its conversion event vector normalization module (3), - a variety of modules specific to license consumption, ranging from standard event vectors, transaction depth, API / batch density, authorization-use deviation, and licensing. 20 structured to enable the calculation of fitness scores at least one feature extraction module (4), - User and service accounts based on current license class, role-authority to segment based on similarity and behavior vector at least one structured undergraduate class contextual segmentation module (5), 25 - Rule for indirect consumption candidates originating from APIs, services, and batches. based pre-filter, contextual anomaly score, and licensing matrix at least configured to enable tagging with verification an indirect / hidden license consumption detection module (6), - assigned high-level permissions, unused modules, process 30 depth, passivity, indirect consumption risk, and the scope of the mandatory work module. 12 By evaluating this information together, a license deviation score is calculated. at least one license deviation score configured to calculate and suitability decision module (7), - Proposed license applicable with constraint-based objective function To ensure the level is determined, the confidence score of the proposal, technical 5 to ensure that it is produced along with the justification and license deviation score At least one constraint-based optimization and licensing proposal is structured. module (8), - the recommended license level for each user and service account, generated confidence score, generated license deviation score, generated indirect consumption 10 risk, affected modules and the technical rationale of the proposal The data is presented in the form of a heat map, trend, risk ranking, and action list. presenting which technical events led to the proposal structured to produce an output in the form of a describable record set at least one notification module (9), 15 - Model coefficients and thresholds of administrator approval / rejection data to be used as active learning input for updating at least one active learning and model structured to provide a system characterized by update module (10) (1).
2. Session logs, module / screen access logs, transaction logs, application programming interface calls, batch jobs, service account activities, user-role mapping, authorization matrix, and licensing Collecting catalog data, records; timestamp, account type, access Matching via channel and module ID, 25 belonging to the same process chain To associate screen, API, and batch logs with a correlation ID, the actual Technical comparison between consumption and allocated license level. data collector configured to provide data so that it can be done, and a resource matching module (2) as in Claim 1 system (1). 30 13 3. Heterogeneous registration formats, Enterprise Resource Planning license consumption. Converting the analysis into a specific event vector, source missing fields Marking duplicate records based on reliability, processing time, and calculation. to extract by correlation, to divide events into fixed time windows, Time window synchronization, identity masking, account type classification, 5 Access channel separation, duplicate event cleaning, and correlation identification. to carry out operations in the form of production, for license analysis to enable the production of comparable technical data models with the structured standard event vector normalization module (3) a 10 as in any of the above characterized claims system (1).
4. Numerical and categorical event vectors specific to license consumption. Generating attributes, processing depth, module variety, API / batch Calculating density, role-authority coverage ratio, and license deviation score 15 characterized by the feature extraction module (4) structured to a system like any of the above requests (1).
5. A module is determined by dividing the number of uniquely accessed modules by the number of authorized modules. Feature extraction module 20 configured to calculate diversity score (4) like any of the above-mentioned claims characterized by system (1).
6. Weighted transaction score up to the maximum transaction score allowed by the relevant license class. Calculate a depth of operation score by dividing the score by the number of read, write, 25 multiplying approval, data export, and management processes with different weights characterized by the feature extraction module (4) structured to a system like any of the above requests (1). 14 7. Number of reading and reporting events versus number of writing, approving, and managing events. an attribute structured to calculate a literacy rate by dividing any of the above requests characterized by the inference module (4) a system like one of them (1).
8. Divide the number of API and batch-related events by the total number of events to get a result. Attribute configured to calculate API / batch density ratio. any of the above requests characterized by the inference module (4) a system like one of them (1).
9. Divide the number of off-hours API / batch events by the total number of API / batch events. an attribute configured to calculate an off-hours automation score any of the above requests characterized by the inference module (4) a system like one of them (1).
10. Evaluate the number of days that have passed since the last successful interaction. configured to calculate a passivity score by dividing it into windows from the above requests characterized by the feature extraction module (4) a system like any other (1).
11. Creating a role-authority scope by dividing the actually used powers into assigned powers. with the feature extraction module (4) configured to calculate the ratio as in any of the above characterized claims system (1).
12. Unused high-level privileges and usage exceeding the license class. an authority by dividing the weighted sum of its candidates by the total scope of authority. Feature inference structured to calculate usage deviation score any of the above requests characterized by module (4) a system like one of them (1). 30 13. License eligibility score: w1*depth of operation + w2*module diversity+w3*mandatory module scope-w4*passivity-w5*indirect consumption structured to calculate using a formula in the form of risk 5 of the above requests characterized by the feature extraction module (4). a system like any other (1).
14. User and service accounts should be matched to the existing license class, role-permission similarity, and Segmenting user behavior according to behavior vectors, role-based To normalize similarity of authority using Jaccard or cosine similarity, the same 10 behavior of accounts with similar role scope within the undergraduate class clustering vectors, instead of general user behavior, the same license to measure the deviation from the expected consumption pattern in its class with the structured undergraduate class contextual segmentation module (5) a 15 as in any of the above characterized claims system (1).
15. API, service account, or batch-based consumption is specific to license consumption. Treating it as a technical event class, in classic access reports Verified consumption from invisible API, service account, and batch sources: 20 implicit / hidden license structured to classify as a technical event from the above requests characterized by the consumption detection module (6) a system like any other (1).
16. High-frequency module access without human user session, same as 25 The service account triggers modules belonging to multiple role classes using batch. The query retrieves or reports data outside the scope of the licensed module. This event occurs if the channel calls the licensed display function in the background. structured to be marked as "candidate for indirect consumption" 16 characterized by the indirect / hidden license consumption detection module (6) a system like any of the above requests (1).
17. Candidate cases; same undergraduate class, same role-authority similarity and same time Judging by normal human user behavior in the window, 5 API / batch density, after-hours automation score, and data volume. structured to calculate contextual anomaly score from its components characterized by the indirect / hidden license consumption detection module (6) a system like any of the above requests (1).
18. Module, operation type, and data triggered by the event marked as an anomaly. matching the object with the mandatory license class in the license catalog, If the match is incompatible with the existing license or role scope, the incident will occur. to label as "verified indirect license consumption" 15 characterized by the structured indirect / hidden license consumption detection module (6) a system like any of the above-mentioned requests (1).
19. Indirect consumption confidence score: a*pre-filter score + b*anomaly score + using a formula in the form of c*license matrix mismatch score Calculating the indirect consumer confidence score, with a value above a defined threshold of 20. risk when constraint-based optimization and license proposal module (8) indirect / hidden license consumption structured to be transferred as input. any of the above requests characterized by the detection module (6) a system like one of them (1).
20. The current license class and actual usage requirements for each account. compare the license deviation score; assigned high-level authorizations, unused modules, processing depth, passivity, indirect consumption risk, and by jointly evaluating the information regarding the scope of the mandatory work module to calculate, with the calculated score, 30 more than required by the account's current license. 17 from classes that carry the risk of high, insufficient, compliant or indirect consumption a license deviation score structured to determine which one it falls into and from the above requests characterized by the suitability decision module (7) a system like any other (1).
21. F (L') = Cost (L') + λ1* Compliance Risk (L') + λ2* Business Continuity Impact The objective expressed as (L') + λ3* Indirect Consumption Risk (L') Solving the function, constraints; mandatory module scope(L')>= actual mandatory Module requirement, depth of field capacity (L') >= observed depth of field, Compliance risk (L') <= threshold, business continuity impact (L') <= threshold 10 to determine, as a result of this function, the technical risk that preserves minimum authority. a proposed license that keeps the threshold below the limit and meets the current usage requirement. constraint-based optimization structured to determine its level and from the above requests characterized by the license proposal module (8) a system like any other (1). 15 22. Current license, proposed license, mandatory module scope, depth of operation. factors such as capacity, compatibility risk and indirect consumption risk by evaluating together, calculating an objective function, and technical constraints. 20 to enable determining a more appropriate license level without violating regulations with the structured constraint-based optimization and license proposal module (8) as in any of the above characterized claims system (1).
23. The recommended license level for each user or service account is 25,000. confidence score, generated license deviation score, generated indirect consumption risk, The data in the form of affected modules and the technical justification of the proposal is heated. Presenting it in the form of a map, trend, risk ranking and action list, which A record set that shows technical events caused the suggestion. The notification module (9) is configured to produce an output in the form of 30 18 as in any of the above characterized claims system (1).
24. Suggestions approved, rejected, or manually corrected by the manager. Using model update data, the approved recommendations are related to the 5 Refused to be kept as a confidence-building sample for undergraduate class The suggestions include "essential business need," "temporary project use," and "exceptional authorization." or adding it to the training pool with a "false positive" label, model their weights, anomaly thresholds, and indirect consumer confidence score updating the coefficients periodically, thus reducing false positives and 10 active designed to reduce false negative rates characterized by the learning and model update module (10) a system like any of the above requests (1). 20 30